Examples
Worked examples
- Is an instance
A federal awarding agency reviewing a discretionary-grant application under 2 CFR 200.206 finds that the applicant has an unresolved single-audit finding from its prior award and no history of managing federal funds of this size. Both are risk indicators. Because their combined severity crosses the agency's internal risk threshold for that program, the agency imposes specific award conditions under 2 CFR 200.208 — converting payments from advance to reimbursement-only and requiring quarterly rather than annual financial reports — rather than issuing the award on standard terms.
- Is an instance
A university's sponsored-programs office runs a portfolio-level risk screen across its active subawards, scoring each subrecipient on indicators including time since last single audit, whether that audit reported findings, entity size/experience, and F&A rate status (negotiated vs. de minimis vs. none). Subrecipients whose combined score crosses the office's internal threshold are moved from standard annual desk reviews to a heightened schedule that adds a mid-year site visit and more granular expenditure documentation — the institution's own application of the risk-based subrecipient monitoring 2 CFR 200.332 requires, using its own indicators and threshold rather than an agency's.
Counter-examples
Looks similar, but isn't
- Not an instance
A recipient simply being audited under the Single Audit Act (2 CFR 200 Subpart F) is not itself a risk indicator — nearly every entity spending $1,000,000 or more in federal awards in a fiscal year is required to have one. It is the audit's <em>findings</em> (a qualified opinion, reported material weaknesses, questioned costs) that function as a risk indicator, not the fact that an audit occurred.
- Not an instance
A single missed report deadline, corrected promptly and without a pattern, is ordinarily monitored as a routine compliance item, not treated as crossing a risk threshold on its own — thresholds are calibrated against materiality and pattern, not against any single minor lapse, and 2 CFR 200.208 itself requires the awarding agency to state the specific rationale before imposing conditions, not merely cite an isolated event.
Editorial commentary
In federal grants compliance, risk indicators and risk thresholds are the two working concepts behind risk-based monitoring: the practice of varying oversight intensity across a portfolio of awards based on assessed risk, rather than applying the same fixed monitoring schedule to every award regardless of actual exposure. The vocabulary is grounded directly in the Office of Management and Budget’s Uniform Guidance, 2 CFR Part 200: 2 CFR 200.206 (“Federal awarding agency review of risk posed by applicants”) requires agencies to evaluate applicant risk before making an award, and 2 CFR 200.208 (“Specific conditions”) governs what an agency can do about elevated risk once identified — up to and including a formal high-risk designation.
Risk indicators: what counts as one
A risk indicator is a specific, checkable fact about an applicant, recipient, or subrecipient — not a vague impression of trustworthiness. 2 CFR 200.206 names the factors a federal awarding agency must consider when assessing risk before an award, and the same categories are what institutions and pass-through entities generally adapt for their own subrecipient risk screens under subrecipient monitoring obligations (2 CFR 200.332):
- Financial stability — the entity’s record of effectively managing financial risk, assets, and resources.
- Quality of management systems — ability to meet the internal-control and financial-management standards 2 CFR Part 200 prescribes.
- Prior federal-award performance history — including a track record of compliance with reporting requirements on previous or current awards.
- Audit findings — results of a Single Audit or other available audit, most concretely OIG or single-audit exceptions and questioned costs.
- Ability to implement statutory, regulatory, or award-specific requirements.
- Applicant status in OMB-designated government-wide repositories (e.g., SAM.gov exclusion or integrity records).
In practice, research administrators and grants officers commonly track a wider working set of indicators that map onto those categories, including: an unresolved or repeated single-audit finding; general financial instability or going-concern language in audited financial statements; new or first-time awardee status with no history of managing federal funds at the relevant scale; an irregular, expired, or unnegotiated F&A (indirect cost) rate; and a documented history of late or noncompliant reporting. No single indicator is disqualifying by itself — each is one input into an overall risk assessment.
Risk thresholds: where the line sits
A risk threshold is the predetermined materiality point at which an accumulation, severity, or specific combination of risk indicators triggers a defined escalation in oversight. Thresholds are what turn a risk assessment from a descriptive exercise into an operational one: they tell a program officer or sponsored-programs office exactly when routine monitoring is no longer sufficient and a heavier response is required. 2 CFR 200.208 lists the escalation options available once a threshold is crossed, which an agency selects and tailors to the specific risk identified:
- Converting payments from advance to reimbursement-only.
- Withholding authority to proceed to a subsequent budget or project period until performance is demonstrated.
- Requiring additional, more detailed, or more frequent financial or programmatic reports.
- Requiring additional project monitoring.
- Requiring the recipient to obtain technical or management assistance.
- Establishing additional prior-approval requirements.
At the far end of that escalation sits formal high-risk designation, the most severe threshold outcome under 2 CFR 200.208. Before imposing any specific condition — not only a high-risk designation — the regulation requires the awarding agency to notify the recipient in writing of the nature of the condition, the reason it is being imposed, what corrective action would resolve it, the timeline for that action, and the method for requesting reconsideration, and to remove the condition promptly once the underlying risk is resolved. A threshold decision is meant to be a documented, reasoned response to specific, cited evidence, not a discretionary label.
How the two concepts fit together in portfolio oversight
Risk indicators and risk thresholds work as a pair across two layers of the grants system:
- Pre-award (agency to applicant): under 2 CFR 200.206, the awarding agency screens applicants against the indicators above before making an award decision, and may build specific conditions into the award terms from day one if a threshold is crossed at that stage.
- Post-award and pass-through (institution to subrecipient): under 2 CFR 200.332’s subrecipient-monitoring requirement, a pass-through entity (a university managing subawards, for example) runs its own comparable risk assessment of each subrecipient and calibrates monitoring intensity — desk review frequency, site-visit cadence, documentation depth — accordingly. An institution’s internal internal controls framework typically defines its own threshold rules for this layer, since 2 CFR Part 200 sets the requirement to assess and respond to risk but does not prescribe a single numeric threshold formula.
This is the same underlying logic that risk-based monitoring (RBM) applies in the clinical-trials context under ICH E6 — concentrate oversight resources where risk indicators show they are actually needed — adapted here to federal financial and programmatic grants compliance rather than trial data integrity.
Related CASRAI resources
For the broader compliance framework these terms sit inside, see the Federal Grant Compliance Checklist and Institutional Internal Controls for Federal Grant Compliance. For the audit findings that most commonly function as risk indicators, see OIG reports and the OMB Compliance Supplement. For the pass-through obligation that applies these concepts to subawards, see subrecipient monitoring.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Risk Indicators and Risk Thresholds"
vocab-term-identifier="https://casrai.org/dictionary/term/risk-indicators-and-risk-thresholds" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/risk-indicators-and-risk-thresholds",
"name": "Risk Indicators and Risk Thresholds",
"identifier": "https://casrai.org/dictionary/term/risk-indicators-and-risk-thresholds",
"description": "A <strong>risk indicator</strong> is a specific, observable fact about an applicant, recipient, or subrecipient that correlates with an elevated likelihood of noncompliance, financial mismanagement, or poor performance on a federal award — for example, a prior single audit finding, financial instability, a new or first-time awardee with no federal-award history, or an irregular or unnegotiated F&A (indirect cost) rate. A <strong>risk threshold</strong> is the predetermined materiality level at which an accumulation or severity of risk indicators requires an awarding agency or pass-through entity to escalate its oversight response — from routine monitoring to enhanced monitoring, imposition of specific award conditions, or formal high-risk designation. Together they form the operating vocabulary of <strong>risk-based monitoring</strong>: instead of applying identical oversight to every award in a portfolio, an agency or institution calibrates monitoring intensity to where the indicators and thresholds say the actual risk is concentrated.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/risk-indicators-and-risk-thresholds",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-18T06:30:49",
"inLanguage": "en"
}






